GDPR (General Data Protection Regulation)
The toughest privacy and security law in the world. Though it was drafted and passed by the European Union (EU), it imposes obligations onto organizations anywhere, so long as they target or collect data related to people in the EU.
Framework Requirements & Categories
Detailed breakdown of the highly precise, accurate control domains defined by GDPR (General Data Protection Regulation).
Lawfulness, fairness and transparency
Data must be processed lawfully, fairly and in a transparent manner in relation to the data subject.
Purpose limitation
Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
Data minimisation
Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
Accuracy
Accurate and, where necessary, kept up to date.
Storage limitation
Kept in a form which permits identification of data subjects for no longer than is necessary.
Integrity and confidentiality
Processed in a manner that ensures appropriate security of the personal data.
Accountability
The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1.
